Saint Agnes Health Care, Inc.
ent_fd55b0af36275083e601ca7c
Disclosures
2
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
24,967
as filed · HHS OCR MD
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Saint Agnes Health Care, Inc.
- Normalized
- saint agnes health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- 🐻California State AGas victim2016-05-05
Saint Agnes Medical Center experienced a Business Email Compromise (BEC) attack on May 2, 2016, where a scammer impersonated the CEO to request W-2 information via email. The incident compromised the 2015 W-2 data (including names, addresses, salaries, withholding info, and Social Security Numbers) of 2,812 employees. No patient data or systems were breached. The organization notified the California Attorney General and offered one year of Experian ProtectMyID Elite credit monitoring to affected employees.
- MARYLANDHHS OCRas victim2015-04-24
Saint Agnes Health Care, Inc. (MD) reported to HHS OCR on 2015-04-24 a Hacking/IT Incident affecting 24,967 individuals. An unauthorized user gained access to employee email accounts via a phishing attack. Breached PHI included demographic, financial, and clinical information. The CE notified HHS, affected individuals, and media. Post-breach, the CE conducted additional phishing-awareness training and implemented additional email safeguards. OCR reviewed the CE's risk analysis and risk management plan.